CVE-2025-13920 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action…
Medium CVSS: 5.3

CVE-2025-13920

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.
Vendor
-
Product
-
CWE
CWE-200
Yayın Tarihi
2026-01-24 13:15:54
Güncelleme
2026-01-26 15:03:33
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar